VDB
GCVE-110-MAGEIA-2015-400
GCVE-110-MAGEIA-2015-400
Advisory Published
Multiple security issues in the DBMail driver for the password plugin,
including buffer overflows (CVE-2015-2181) and the ability for a remote
attacker to execute arbitrary shell commands as root (CVE-2015-2180).
An authenticated user can download arbitrary files from the web server
that the web server process has read access to, by uploading a vCard with
a specially crafted POST (CVE-2015-5382).
The roundcubemail package has been updated to version 1.0.6, fixing these
issues and several other bugs, however the installer is currently known
to be broken.
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Mageia | roundcubemail | 1.0.6-1.1.mga5 (unaffected), 0 (affected) | — |
References
Browse GCVE Records
74,132 records in the GCVE database · Updated July 20, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.